Hi, I'm using this search: | tstats count by host where index="wineventlog"
to attempt to show a unique list of hosts in the wineventlog index.
But I get this error: Error in 'tstats' command: Invalid argument: 'index=wineventlog'
How do I form my search to use tstats (not stats) to return a unique list of hosts within a specific index? (in this case, wineventlog)?
What about - | tstats count where index="wineventlog" by host
? works for me ...
Try the following: | tstats count where index="wineventlog" by host
.
Perfect, thanks bro.